TECH
The Chinese tactic of AI model distillation
The United States has accused six Chinese artificial intelligence companies of using large-scale AI model distillation to extract capabilities from systems developed by U.S. companies. The accusation appears in a joint advisory published by the National Security Agency (NSA), the FBI, and the Cybersecurity and Infrastructure Security Agency (CISA).
The agencies identify DeepSeek, Moonshot AI, Alibaba, MiniMax, StepFun, and Z.AI, stating that these companies utilized U.S. models to accelerate the development of their own systems. According to U.S. authorities, these operations have been ongoing since at least late 2024 and involved large volumes of requests sent to frontier models.
The accusation marks a new development in a dispute that had already reached the diplomatic level. In April, the U.S. State Department warned allied governments about alleged distillation campaigns conducted by Chinese companies. The new document now adds a joint assessment from three federal agencies involved in intelligence, homeland security, and law enforcement.
According to the advisory released by the NSA, the Chinese companies reportedly distributed their activity across various accounts, providers, and infrastructure in an attempt to bypass usage limits and mechanisms designed to detect anomalous access patterns.
Authorities describe the use of APIs, intermediary services, and other mechanisms intended to mask the origin of requests. This approach allowed for the distribution of large volumes of queries across multiple accounts and services, making it difficult for model providers to detect the operations.
The NSA, FBI, and CISA classify these practices as "adversarial distillation," stating that they enable Chinese companies to acquire the capabilities of U.S. frontier models without bearing the full costs associated with the original training.

The agencies add that these operations took place "likely with the knowledge of the Chinese government." This phrasing reflects an assessment by U.S. authorities rather than an independently proven fact.
Beijing has rejected the accusations. According to Reuters, Chinese Foreign Ministry spokesperson Mao Ning stated that the country's progress in artificial intelligence stems from its own scientific and technological capabilities and accused Washington of making baseless claims.
Model distillation is a legitimate AI technique...AI model distillation is not, in itself, an illicit practice. It is a machine learning technique that allows knowledge to be transferred from a more capable model to another system—usually one that is smaller or more efficient.
The "student" model learns from the responses or distributions produced by the "teacher" model, which can reduce the resources needed to achieve specific capabilities. TecheNet has previously explained how AI model distillation works and what its main applications are.
The NSA itself distinguishes between legitimate use of the technique and operations it classifies as "adversarial distillation." The accusation, therefore, focuses not on the existence of distillation itself, but on the manner in which US models were allegedly queried on a large scale—using methods designed to bypass access restrictions and protection mechanisms.
OpenAI presented a similar distinction in a document submitted to the US Congress. The company stated it had identified accounts linked to DeepSeek that sought to bypass access restrictions, use intermediaries to mask the origin of requests, and programmatically gather responses from its models.
Some of the allegations now compiled by US authorities had already been made public by companies in the sector.
In February, Anthropic accused DeepSeek, Moonshot AI, and MiniMax of conducting distillation campaigns against Claude. According to the company, the three labs generated over 16 million interactions using approximately 24,000 fraudulent accounts.
These were Anthropic's accusations against DeepSeek, Moonshot, and MiniMax—marking one of the first instances where a major US lab presented figures regarding the scale of the alleged operations. According to data published by Anthropic, MiniMax was reportedly responsible for over 13 million interactions, Moonshot for approximately 3.4 million, and DeepSeek for more than 150,000.
Anthropic stated that it linked the campaigns to the respective laboratories using IP addresses, request metadata, infrastructure indicators, and information obtained from other industry players. However, these findings come from the company itself—an entity that is simultaneously one of the alleged targets and a competitor to the Chinese laboratories.
OpenAI also pointed to activity by DeepSeek...OpenAI had previously made similar allegations. In a report submitted to a U.S. House of Representatives committee, the company stated it had observed activity associated with DeepSeek consistent with what it classified as adversarial distillation.
According to OpenAI, they detected accounts linked to employees of the Chinese company, access via intermediaries masking the origin of requests, and tools designed to automatically gather responses from U.S. models.
These earlier allegations are significant because they show that the new federal advisory is not the first time these suspicions have been raised. The new element lies primarily in the formal, joint nature of the accusations made by the NSA, FBI, and CISA, the identification of six specific companies, and the characterization of the activity as part of a larger-scale campaign.
The joint advisory from the three agencies places model distillation within a broader national security context. U.S. authorities argue that accessing the capabilities of frontier models could reduce some of the computational, financial, and energy costs required to develop competing systems.
Washington also links the development of advanced models in China to potential military and cybersecurity applications. This connection is part of the U.S. strategic assessment and does not, in itself, prove that the described distillation operations directly resulted in such capabilities.
The release also comes at a time of dialogue between Washington and Beijing regarding artificial intelligence. According to Reuters, the United States and China were preparing for bilateral talks on AI safety for mid-September.
The difference compared to previous accusations lies, therefore, less in the existence of distillation itself and more in the institutional status and scope of the accusation. What began with allegations from companies like Anthropic and OpenAI—and progressed to a U.S. diplomatic warning in April—has now culminated in a joint advisory from the NSA, FBI, and CISA that identifies six Chinese companies and describes the activity as a systematic, industrial-scale campaign.
mundophone
No comments:
Post a Comment